Security Review
valory-xyz/open-autonomy
Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment…
Produces a dynamic CycloneDX BOM by executing a command under the cdxgen safer-exec sandbox with tracebom, tracing dlopen shared-library loads, eBPF HTTP URL access, cryptographic library and…
$ npx skills add cdxgen/cdxgen --skill runtime-trace-bom -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cdxgen/cdxgen runtime-trace-bom --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-plugin/skills/runtime-trace-bom .claude/skills/runtime-trace-bom && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "runtime-trace-bom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/runtime-trace-bom into .claude/skills/runtime-trace-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-trace-bom", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/runtime-trace-bomType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cdxgen/cdxgen --skill runtime-trace-bom -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cdxgen/cdxgen runtime-trace-bom --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .agents/skills && cp -r skills-src/claude-plugin/skills/runtime-trace-bom .agents/skills/runtime-trace-bom && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "runtime-trace-bom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/runtime-trace-bom into .agents/skills/runtime-trace-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-trace-bom", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cdxgen/cdxgen --skill runtime-trace-bom -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cdxgen/cdxgen runtime-trace-bom --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/claude-plugin/skills/runtime-trace-bom .cursor/skills/runtime-trace-bom && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "runtime-trace-bom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/runtime-trace-bom into .cursor/skills/runtime-trace-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-trace-bom", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cdxgen/cdxgen.git --path claude-plugin/skills/runtime-trace-bom--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cdxgen/cdxgen --skill runtime-trace-bom -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cdxgen/cdxgen runtime-trace-bom --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/claude-plugin/skills/runtime-trace-bom .gemini/skills/runtime-trace-bom && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "runtime-trace-bom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/runtime-trace-bom into .gemini/skills/runtime-trace-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-trace-bom", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cdxgen/cdxgen runtime-trace-bomInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cdxgen/cdxgen --skill runtime-trace-bom -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .github/skills && cp -r skills-src/claude-plugin/skills/runtime-trace-bom .github/skills/runtime-trace-bom && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "runtime-trace-bom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/runtime-trace-bom into .github/skills/runtime-trace-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-trace-bom", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cdxgen/cdxgen --skill runtime-trace-bom -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cdxgen/cdxgen runtime-trace-bom --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cdxgen/cdxgen.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/claude-plugin/skills/runtime-trace-bom .opencode/skills/runtime-trace-bom && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "runtime-trace-bom" agent skill from https://github.com/cdxgen/cdxgen/tree/master/claude-plugin/skills/runtime-trace-bom into .opencode/skills/runtime-trace-bom/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "runtime-trace-bom", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
runtime-trace-bomProduces a dynamic CycloneDX BOM by executing a command under the cdxgen safer-exec sandbox with tracebom, tracing dlopen shared-library loads, eBPF HTTP URL access, cryptographic library and…
Runtime Trace Bom is an agent skill from cdxgen/cdxgen. Produces a dynamic CycloneDX BOM by executing a command under the cdxgen safer-exec sandbox with tracebom, tracing dlopen shared-library loads, eBPF HTTP URL access, cryptographic library and cipher-suite usage, child process execution, and filesystem mutations. Use when asked what a program actually loads or calls at runtime, for a dynamic or runtime SBOM, to observe a binary's real behaviour, or to trace network and crypto usage of a process.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Supply chain security and Cryptography. The repository describes itself as: Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI/CD pipeline with…. The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 5497d57. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
cdxgen.github.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Runtime Trace Bom loads about 2k tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 677 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cdxgen/cdxgen at commit 5497d57, republished under its Apache-2.0 licence (© cdxgen). 677 words, ~1,957 tokens.
.claude/skills/runtime-trace-bom/SKILL.md (or your agent's skills folder).tracebom runs a command under the @cdxgen/safer-exec sandbox and records
what it actually does: which shared libraries it dlopens, which HTTP URLs it
reaches, which crypto primitives it exercises, which children it spawns, and
which files it mutates. The output is a CycloneDX BOM with library components
and enumerated services.
This is observation of real execution, not static inference. It complements
sbom-generate rather than replacing it: a trace shows only what the traced run
exercised, so it under-reports by design.
Read reference/safety.md first.
tracebom executes the user's command. Treat every invocation as a
confirm-first action:
--cmd you intend to run and the sandbox limits.The sandbox restricts filesystem, network, and process behaviour. It is a containment boundary, not a guarantee against malicious code.
tracebom --cmd "node app.js" -o /absolute/path/to/bom.jsonAliases as a project type: -t dynamic / -t trace.
Evidence recorded on traced components uses
technique=instrumentation, scope=required, confidence 0.8/0.5, plus
hashes and OS package attribution.
| Flag | Default | Purpose |
|---|---|---|
-d, --working-dir | cwd | Working directory for the traced process |
--timeout | 60000 ms | Trace timeout |
--trace-period | — | Stop tracing after N seconds |
--max-memory | 512 MB | Memory ceiling |
--max-cpu | — | CPU cores, fractional (0.5 = half a core) |
--max-processes | 64 | Process count ceiling |
--strict | false | Treat sandbox setup warnings as hard errors |
Use --trace-period for long-running or persistent commands — a server will
otherwise run until --timeout. Use --strict in CI so a degraded sandbox
fails loudly instead of silently tracing less.
| Flag | Default | Purpose |
|---|---|---|
--read-paths | — | Extra read paths, comma-separated |
--write-paths | OS tmpdir | Sandbox write paths |
--allow-hidden | true | Allow hidden files and directories |
--diff | false | Track files created, modified, or deleted |
--diff is the flag to reach for when the user's question is "what did this
installer/build script change?"
| Flag | Default | Purpose |
|---|---|---|
--disable-network | true | Network off inside the sandbox |
--trace-http-urls | false | eBPF HTTP URL tracing; automatically enables network |
--allow-host | — | Hostnames the process may reach |
--allow-port | — | TCP ports allowed |
--allow-url | — | Fine-grained URL allow rules |
--allow-listen | — | IPs or ip:port the process may bind |
Network is off by default, and --trace-http-urls turns it on. Say that out
loud when enabling it — the user is choosing to let the traced process reach the
network.
tracebom --cmd "node app.js" \
--trace-http-urls \
--allow-host api.example.com --allow-port 443 \
-o /absolute/path/to/bom.jsonKeep the allowlist narrow, consistent with the host-allowlist rule in reference/safety.md.
Platform constraint: eBPF HTTP URL tracing is Linux-only, needs kernel
= 5.8, and requires
CAP_BPF. On macOS or Windows it will not work — do not present its absence as a cdxgen failure.
| Flag | Default | Purpose |
|---|---|---|
--trace-crypto | true | eBPF crypto library and cipher-suite tracing |
--crypto-probe-mode | tls-only | tls-only, or operations for digest, encrypt, sign |
tracebom --cmd "node app.js" \
--trace-crypto --crypto-probe-mode operations \
-o /absolute/path/to/bom.jsonAlso Linux-only with kernel >= 5.8. Use operations when the user wants
observed cryptographic operations rather than just negotiated TLS; pair it with
crypto-bom for the static side of the same question.
| Flag | Default | Purpose |
|---|---|---|
--trace-exec | false | Log every child process spawned |
--allow-exec | — | Executables the command may run |
--block-exec | — | Executables to block |
--block-fork | false | Prevent forking new processes |
--allow-envs | — | Host env vars allowed through the sandbox |
--trace-exec is valuable for build scripts and postinstall hooks, where the
interesting behaviour is what gets spawned.
--allow-envs passes host environment variables into the sandbox. Do not pass
credential-bearing variables unless the user explicitly asks and understands
they will be available to the traced process.
| Flag | Default |
|---|---|
-o, --output | bom.json |
--spec-version | 1.7 |
--project-name | — |
--project-version | — |
--print | false |
bom-evidence for reachability before concluding a dependency is unused.cdxi, .instrumented isolates the trace-derived components.© cdxgen, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in claude-plugin/skills/runtime-trace-bom of cdxgen/cdxgen.
Open the folder on GitHubat commit 5497d57
Runtime Trace Bom next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Runtime Trace Bom this skillcdxgen/cdxgen | 1.1k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Security Reviewvalory-xyz/open-autonomy | 129 | — | ~11k | Automated safety check: Notes | Apache-2.0 | |
| Implementing Sigstore For Software Signingmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.2k | Automated safety check: Notes | Apache-2.0 | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 479 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Eu CraSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 939 | 1 repos | ~4k | Automated safety check: Pass | MIT |
valory-xyz/open-autonomy
Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment…
mukul975/Anthropic-Cybersecurity-Skills
Implements Sigstore-based software signing and verification using Cosign keyless signing, Rekor transparency log verification, and Fulcio certificate authority integration to establish cryptographic…
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert EU Cyber Resilience Act (CRA) advisor for Regulation (EU) 2024/2847 — mandatory cybersecurity and vulnerability handling requirements for all products with digital elements (PDEs) sold in the…
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
cdxgen/cdxgen
Generates AI-BOM, MCP inventory, AI skill inventory, and AI authorship provenance documents with cdxgen, cataloging models, inference services, Hugging Face purls, MCP servers and their…
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
cdxgen/cdxgen
Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…
cdxgen/cdxgen
Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…
cdxgen/cdxgen
Signs and verifies CycloneDX BOMs using cdxgen's native JSON Signature Format (JSF) implementation via cdx-sign and cdx-verify, supporting granular component, service, and annotation signatures…
cdxgen/cdxgen
Converts CycloneDX BOMs to SPDX 3.0.1 JSON-LD or between CycloneDX spec versions with cdx-convert, and validates BOMs against JSON schema, deep consistency checks, and OWASP SCVS and EU Cyber…
Categories
Produces a dynamic CycloneDX BOM by executing a command under the cdxgen safer-exec sandbox with tracebom, tracing dlopen shared-library loads, eBPF HTTP URL access, cryptographic library and…. Runtime Trace Bom is an agent skill from cdxgen/cdxgen. Produces a dynamic CycloneDX BOM by executing a command under the cdxgen safer-exec sandbox with tracebom, tracing dlopen shared-library loads, eBPF HTTP URL access, cryptographic library and cipher-suite usage, child process execution, and filesystem mutations.
Runtime Trace Bom fits situations like: asked what a program actually loads; calls at runtime; observe a binarys real behaviour; trace network and crypto usage of a process.
Run `npx skills add cdxgen/cdxgen --skill runtime-trace-bom -a claude-code`. Or copy the skill folder (claude-plugin/skills/runtime-trace-bom in cdxgen/cdxgen) into .claude/skills/runtime-trace-bom in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cdxgen/cdxgen --skill runtime-trace-bom -a codex`. Or copy the skill folder (claude-plugin/skills/runtime-trace-bom in cdxgen/cdxgen) into .agents/skills/runtime-trace-bom in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cdxgen/cdxgen --skill runtime-trace-bom -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/runtime-trace-bom, .gemini/skills/runtime-trace-bom, .github/skills/runtime-trace-bom and .opencode/skills/runtime-trace-bom in your project.
SKILL.md names no scripts, command-line tools or credentials: Runtime Trace Bom is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: cdxgen.github.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Runtime Trace Bom is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Runtime Trace Bom: Security Review (valory-xyz/open-autonomy, 129 stars), Implementing Sigstore For Software Signing (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 479 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cdxgen (a GitHub organization) maintains it in cdxgen/cdxgen, which has 1,085 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 6, 2026.
Source: cdxgen/cdxgen on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.